Latest CVE Feed
-
5.5
MEDIUMCVE-2022-49896
In the Linux kernel, the following vulnerability has been resolved: cxl/pmem: Fix cxl_pmem_region and cxl_memdev leak When a cxl_nvdimm object goes through a ->remove() event (device physically removed, nvdimm-bridge disabled, or nvdimm device disabled)... Read more
Affected Products : linux_kernel- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2022-49899
In the Linux kernel, the following vulnerability has been resolved: fscrypt: stop using keyrings subsystem for fscrypt_master_key The approach of fs/crypto/ internally managing the fscrypt_master_key structs as the payloads of "struct key" objects conta... Read more
Affected Products : linux_kernel- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2024-9641
The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ... Read more
Affected Products : luckywp_table_of_contents- Published: Dec. 12, 2024
- Modified: May. 07, 2025
-
4.8
MEDIUMCVE-2024-9881
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : learnpress- Published: Dec. 12, 2024
- Modified: May. 07, 2025
-
6.0
MEDIUMCVE-2024-26328
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.... Read more
Affected Products : qemu- Published: Feb. 19, 2024
- Modified: May. 07, 2025
-
5.3
MEDIUMCVE-2024-26327
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.... Read more
Affected Products : qemu- Published: Feb. 19, 2024
- Modified: May. 07, 2025
-
5.5
MEDIUMCVE-2020-36774
plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).... Read more
Affected Products : glade- Published: Feb. 19, 2024
- Modified: May. 07, 2025
-
5.9
MEDIUMCVE-2024-20921
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle Gra... Read more
- Published: Feb. 17, 2024
- Modified: May. 07, 2025
-
5.3
MEDIUMCVE-2024-20915
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login - SSO). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network acc... Read more
Affected Products : application_object_library- Published: Feb. 17, 2024
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2024-2702
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. ... Read more
Affected Products : olive_one_click_demo_import- Published: Mar. 20, 2024
- Modified: May. 07, 2025
-
5.3
MEDIUMCVE-2023-7232
The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data... Read more
Affected Products : backup_and_restore_wordpress- Published: Mar. 26, 2024
- Modified: May. 07, 2025
-
4.3
MEDIUMCVE-2024-1745
The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Au... Read more
- Published: Mar. 26, 2024
- Modified: May. 07, 2025
-
5.3
MEDIUMCVE-2024-29735
Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set permissions for all parent folders of log folder, in default con... Read more
Affected Products : airflow- Published: Mar. 26, 2024
- Modified: May. 07, 2025
-
7.2
HIGHCVE-2024-25420
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.... Read more
Affected Products : openfire- Published: Mar. 26, 2024
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2024-25421
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.... Read more
Affected Products : openfire- Published: Mar. 26, 2024
- Modified: May. 07, 2025
-
6.1
MEDIUMCVE-2024-2278
Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : woocommerce_product_filter- Published: Apr. 01, 2024
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2024-29433
A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.... Read more
Affected Products : alldata- Published: Apr. 01, 2024
- Modified: May. 07, 2025
-
4.1
MEDIUMCVE-2024-29435
An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.... Read more
Affected Products : alldata- Published: Apr. 01, 2024
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2024-1274
The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)... Read more
- Published: Apr. 02, 2024
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2024-31002
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.... Read more
Affected Products : bento4- Published: Apr. 02, 2024
- Modified: May. 07, 2025